In December, a co-founder of a shopping startup asked a question in a Slack channel.
Phoebe Gates wanted to know whether the automatic cookie drop was live across every retail partner, including on shoppers who had never touched her company's coupon pop-up. She framed it around whether the company was monetizing all GMV.
That is not a bug report. Nobody in the history of software has asked whether a defect was live on all sites so they could confirm it was earning.
Seven months later, when Bloomberg called, a Phia spokesperson said the company had learned of the problem within the last 24 hours.
Between the question and the answer: 201 days, and, per an internal chart Bloomberg reviewed, average daily revenue that fell from roughly $80,000 to somewhere between $10,000 and $28,000 the moment the feature went dark. Bloomberg's analysis put the share of June merchandise value attributable to the practice at around 51 percent.
That's the scandal, and you've read it already. TechCrunch ran it. Fortune ran it. The Post ran it with the word prison in the headline.
Here is what none of them ran.
Every transaction Phia claimed passed through a network built to distribute exactly those commissions. That network's own chief marketing officer sat down with ADOTAT before any of this broke and named, unprompted, the precise structural flaw that made it possible. Then, in the same conversation, sold the channel on the opposite premise.
The Phia story is a startup behaving badly. The real story is that the machine worked as designed, that two federal prison sentences twenty years ago changed nothing about how it works, and that the people best positioned to catch it are paid by the volume they'd have to catch.
What The Extension Did, In Plain English
Strip the vocabulary and the mechanism is a pickpocketing technique with a venture round.
Per Inc., testing by Bloomberg, by rival Capital One Shopping, and by researcher Ben Edelman found affiliate clicks registering without meaningful user interaction. The extension opened a background tab. It inserted Phia's referral code. Sometimes it overrode the code of the publisher who had actually sent the shopper there.
Here is what that means in a life.
Someone tests eleven pairs of running shoes and writes three thousand words about arch support. You read it. You trust them. You click their link. You buy the shoes.
They get nothing.
In a tab you never saw open, that rendered nothing and showed you nothing, a company you have no relationship with raised its hand and said: that one was mine.
Bloomberg reported the drop wasn't an anomaly but a purposefully built feature with an on/off switch. Somebody wrote that toggle. Somebody named the variable, and that name is sitting in a git history right now with a timestamp on it. And when an engineer flagged the practice as a compliance violation, Bloomberg reported that co-founder Sophia Kianni encouraged the team to keep the cookies firing.
The engineer said it broke the rules. The founder said keep going. The cookies kept dropping.
There was a version where nobody knew. It required the engineer to stay quiet. He didn't. He is the only person in this story who behaved correctly, and his reward is to be an unnamed noun in somebody else's scandal.
The CMO Said It Out Loud
Cristy Garcia is the chief marketing officer of Impact.com, the partnership platform that distributes the commissions in question. She appeared on The ADOTAT Show before any of this surfaced.
Asked which myth about affiliate marketing she'd most like to kill, she said the perception that the channel is less than other channels, that it's full of bottom feeders, that it produces no incremental value. Then she named why people think that. Three reasons. The first one out of her mouth was attribution issues and last-click bias.
Six minutes later, explaining why CMOs are finally taking affiliate seriously, she pitched it as the channel where you only pay for results, where everything is measured and traceable back to a source, where you can see it and optimize it.
Both statements are true. That's the problem.
The channel does only pay for results. It just cannot tell the difference between producing a result and being present when one occurs. Last touch pays whoever's cookie is last in the jar at checkout. That is the entire adjudication. There is no second step. Nobody asks whether a human clicked. Nobody asks whether a page rendered, whether a link was visible, whether the referral did any work of persuasion at all.
The cookie is not evidence that somebody was convinced. The cookie is evidence that there is a cookie.
Garcia named the defect in the first four minutes and then, in good faith, sold the channel on a promise the defect makes impossible to keep. She was describing a reputation problem. She was actually describing an attack surface.
ADOTAT has contacted Impact.com and Garcia for comment on this piece.
Nobody's Dream Tool Catches The Thief
Late in that same conversation, there's a question about what AI tool she'd build if she could build anything.
Her answer: something that recommends which partners to engage, which placements will drive impact on a launch, what contract changes would move sales ten percent.
Sit with that for a second, because it is not a gotcha. It is a perfectly reasonable answer from a very good marketer, and that is precisely what makes it damning.
Nobody in this industry dreams about the tool that catches the publisher stealing.
Not because anyone is corrupt. Because of where the money sits. The network takes a cut of what flows through it. Volume is revenue. An anomaly detection system that flags your largest new publisher is a system that shrinks your own P&L, and every intermediary at every layer of this business faces that identical arithmetic.
The detection problem, meanwhile, is not hard. It is the opposite of hard. A publisher whose conversions arrive with no preceding click is the single most obvious pattern in affiliate marketing. It's a query. Click-to-conversion ratio, sorted descending, and Phia would have been sitting at the top of it in January.
That query is exactly what got run in 2006.
Ben Edelman Caught It. He Caught It The First Time Too.
In 2006, eBay brought in a researcher to run compliance checks on affiliates it suspected of stuffing cookies. That work fed directly into the prosecutions that turned cookie stuffing from a contract dispute into federal wire fraud.
The researcher was Ben Edelman.
In 2026, the independent analyst who reviewed Phia's code, took apart three separate cookie stuffing features, and corroborated Bloomberg's findings was Edelman.
Twenty years. The same scheme. The same man holding the flashlight.
His assessment: a multipart effort built to inflate Phia's revenue with no benefit to merchants, and a company that should have spent more time learning the contracts it was bound by. Phia declined to comment on it.
Read that sequence again and notice what it actually proves. It is not that Edelman is unusually gifted. It's that the industry's detection capability, twenty years on, is still one guy with a browser and a hypothesis.
Two Men Went To Prison For This
Cookie stuffing is not a gray area. It is a federal crime, it has been prosecuted, and the paperwork is public.
Ariel Givner of Givner Law described the conduct on X as typically treated as federal wire fraud in US courts, carrying exposure up to twenty years plus fines and restitution. She isn't floating a theory. She's describing settled ground.
Brian Andrew Dunning pleaded guilty in San Jose to wire fraud, admitting that between May 2006 and June 2007 he ran a scheme to defraud eBay through cookie stuffing. His company took roughly $5.2 million. The mechanism was two free widgets any site owner could install. The embedded code silently redirected visitors' browsers to eBay's tracking server and left a cookie carrying his ID, with no click, no eBay content, and no awareness by the person it happened to.
Read that description. Then read what Phia's extension did.
Same machine. Better typography.
Dunning got fifteen months. He also hosted a popular podcast about critical thinking, a detail no editor would permit in fiction.
Shawn Hogan, eBay's biggest affiliate, pleaded to one count and got five months and a $25,000 fine against roughly $28 million in alleged fraudulent commissions.
Christopher Kennedy drew six months, three years of supervised release with restrictions on computer use, and $407,934.39 in restitution. His case settled the part everyone forgets: building the tool is enough.
The statute is 18 U.S.C. § 1343. Twenty years, a $250,000 fine or double the gain, plus restitution.
And the theory that made it stick is elegant the way a guillotine is elegant. Prosecutors argued the cookies themselves, crossing state lines, satisfied the wire element. Whether the money crossed a state line was irrelevant. The cookie is the wire. That won in the Northern District of California, and then won again.
One more, for whichever general counsel is reading this. When Hogan and Dunning denied cookie stuffing to their affiliate network, prosecutors used the denials as evidence of intent to deceive.
Now go back and read within the last 24 hours one more time.
Downstream, People Were Getting Robbed
Cookie stuffing has victims and they are not Nike.
It is a transfer. Every commission claimed on a sale you didn't drive comes out of whoever drove it. Bloggers, review sites, creators, the long tail of people for whom affiliate income is rent rather than a metric on a board slide.
Inc. reported that affiliate operators had been watching unexplained revenue dips break their projections, and that some spotted Phia in their own tracking systems taking credit for commissions it never earned.
They knew before the press did. They just didn't have Bloomberg's number, and nobody profiles a coupon blogger.
Impact.com suspended Phia after Bloomberg's first story and began reallocating unpaid commissions going back to June 20. Which raises the only question that matters for this piece: the suspension came after a reporter called. What would have triggered it otherwise?
And an FTC record Inc. obtained under FOIA shows consumer complaints about Phia's undisclosed advertising arriving in January. The same month the company closed a $35 million round.
So: Prison?
Almost certainly not, and the reasons are the story.
No charges have been filed. No agency has announced an investigation. The FTC complaints are consumer complaints, not enforcement. Twenty years is a statutory maximum, which is a number nobody gets. Phia is also doing the one thing Hogan and Dunning never did, which is paying it back before anyone made them, and early voluntary restitution is precisely what keeps a wire fraud file from becoming a wire fraud case. The likelier exposure is civil. Clawbacks, breach of contract, the Honey track rather than the Dunning track.
So no. Barring something not yet public, nobody is going to prison.
But watch what that answer is not.
It is not "this wasn't a crime." The conduct has been prosecuted. The theory was tested and held. The sentences were served. Whether anyone charges it is a question about prosecutorial appetite, not about whether the law reaches the behavior. The coverage keeps welding those together. They are not the same question.
The Part That Should Actually Bother You
Twenty years ago this was done by men with a MySpace widget and a box in a closet. Grand juries indicted them. They went to federal prison. Nobody wrote a profile calling them disruptive.
Today the identical mechanism, shipped inside a venture-backed extension with celebrity investors and a surname that opens every door in the country, gets called a technical anomaly, gets a spokesperson, gets a statement about upcoming product features, and gets to keep the money until a reporter calls.
The code didn't change. The lawyers did.
But that's the smaller finding.
The bigger one is that two federal prosecutions, a landmark wire fraud theory, a class action against Honey, and twenty years of trade press produced a compliance clause in a contract nobody audits. Not a verification layer. Not a detection standard. Not a single required disclosure about how a click became a conversion.
We built an industry that cannot distinguish between persuading a customer and being nearby when they buy. Then we act astonished, roughly once a decade, when somebody notices the second one is far cheaper to fake.
Dunning got fifteen months for $5.2 million.
Phia is issuing refunds and shipping a digital closet.
How this was reported: built on Bloomberg's July 7 and August 11 investigations, which broke this story and obtained the internal Slack messages, plus follow-up reporting from Fortune, TechCrunch, Inc. and the New York Post, including Inc.'s FOIA production on the FTC complaint record and its reporting on the Capital One Shopping and Edelman testing. Primary source documents come from the U.S. Attorney's Office for the Northern District of California in the Dunning prosecution. Cristy Garcia's remarks are from a previously recorded ADOTAT Show interview conducted before this story surfaced; Impact.com and Garcia were contacted for comment before publication. ADOTAT has not independently reviewed the Slack messages and all characterizations of them are Bloomberg's reporting; the 51 percent figure is Bloomberg's analysis as reported by the New York Post; the 201-day span is calculated from the December 18 message to the July 7 shutoff. Phia was contacted for comment on August 13. No charges have been filed against any individual named here. ADOTAT has no financial relationship with Phia, Impact.com, Capital One Shopping, or any investor named, and no subject received advance review.


